List your product on Stack Search

Get in front of thousands of GRC decision-makers

APRA, ASIC Press Superannuation CEOs on AI, Cyber Risk & Crisis Preparedness

APRA, ASIC Press Superannuation CEOs on AI, Cyber Risk & Crisis Preparedness

By
Key Takeaways
  • AI Is Intensifying Existing Cyber Risks: Superannuation executives broadly agreed that frontier AI is increasing the speed, scale and sophistication of cyber threats, placing greater pressure on cyber fundamentals, governance and operational resilience.
  • Board Preparedness Remains Uneven: Participants acknowledged differences in board engagement and director capability across organizations, with practical education and capability building identified as important to effective oversight.
  • Third-Party Concentration Creates Systemic Exposure: Reliance on a relatively small number of material service providers and technology platforms is creating shared vulnerabilities, while transparency and assurance across complex supply chains remain challenging.
  • Crisis Exercises Are Exposing Governance Weaknesses: Simulations involving cyber incidents, provider failures and operational disruptions have revealed problems with escalation, delegation and communication that may not be apparent from policies and documentation alone.
Deep Dive

At two CEO roundtables in June, the Australian Prudential Regulation Authority and Australian Securities and Investments Commission asked industry leaders to consider cyberattacks complicated by artificial intelligence, failures at critical service providers and crises that spill across organizational boundaries. The regulators published notes from the discussions Tuesday.

The meetings brought together executives from a cross-section of the superannuation industry. The conversation ranged across frontier AI, cyber and operational resilience, crisis preparedness, climate reporting and financial advice reform. But much of it returned to a more immediate question: whether organizations are actually prepared for the risks they already know about.

On cyber, the discussion appears to have moved past awareness. Participants broadly agreed that AI is increasing the speed, scale and sophistication of existing threats. That does not necessarily demand an entirely new defensive playbook. If anything, it makes the old fundamentals harder to ignore.

Strong cyber controls, effective governance and resilient operating models remain central. The difficulty is that organizations have not developed those capabilities evenly. Participants acknowledged varying levels of organizational maturity, including differences in board engagement and the capabilities of individual directors. Giving boards the education and practical understanding required to oversee these risks remains a challenge.

That distinction between knowing about a risk and being ready for it ran through the discussion.

Participants emphasized that cooperation across the industry does not dilute the accountability of individual organizations. Superannuation entities still need to understand their own risk profiles, prepare for incidents and know how they will respond when those incidents occur. Recovery and remediation matter too. Resilience, in this telling, is something demonstrated after a control fails as much as before it does.

When Your Supplier Becomes Everyone’s Problem

The harder problem may sit beyond an organization’s own walls. Superannuation funds increasingly depend on material service providers and technology platforms that are also used by their peers. Participants identified that concentration as a potential source of systemic vulnerability, particularly where a relatively small number of providers support large portions of the industry.

A fund can manage its own technology well and still inherit the weaknesses of a provider it depends on. When several funds depend on the same provider, the consequences of that weakness no longer belong neatly to one organization.

APRA’s CPS 230 operational risk management standard has sharpened attention on critical operations and supplier dependencies, participants said. It has not made the underlying problem simple. Transparency and assurance become harder as supply chains grow more complicated, and the roundtables considered whether traditional approaches to third-party oversight are sufficiently dynamic for those relationships.

Technology modernization, cyber resilience and operational capability all require continued investment. Participants also saw industry collaboration and information sharing as useful ways of strengthening resilience across the sector.

There is an uncomfortable tension there. Some of the risks are shared. The accountability is not.

APRA and ASIC made clear through the discussion that collaboration does not relieve individual entities of responsibility for their own preparedness.

The Crisis Plan Meets the Crisis

The regulators then turned to what they called “polycrisis” scenarios: situations in which organizations face several disruptions at the same time. Geopolitical risks are appearing more frequently in board and executive discussions, participants said. Trying to predict precisely which event will become the next crisis, however, was not the point. The emphasis was on building organizations capable of making decisions and continuing to operate when the circumstances are uncertain.

Executives discussed lessons from simulations involving cyber incidents, material service provider failures, operational disruptions and significant transformation programs. Those exercises have a habit of exposing problems that look perfectly manageable on paper.

Governance arrangements can prove less clear in practice. Delegations can become uncertain. Communication breaks down. Escalation pathways that seemed obvious when they were written become less obvious when people have incomplete information and little time to act.

That is why participants placed weight on regular testing, clearly defined escalation pathways and robust communication arrangements. Crisis exercises were described not simply as tests of technical recovery, but as ways of finding weaknesses in how organizations make decisions under pressure.

The consequences of a severe event may also extend beyond the institution experiencing it. Participants acknowledged that some stress scenarios could require coordination among superannuation entities, APRA, ASIC and other government agencies.

The June meetings included executives from Australian Retirement Trust, CBUS and AMP on June 24. Executives from Australian Ethical Superannuation, BT Funds Management, CareSuper, Commonwealth Superannuation Corporation, Team Super and Vanguard Super attended the June 30 session.

The regulators also used the roundtables to discuss risks that are still developing. Agentic AI raised questions about AI-enabled interactions with consumers. Climate-related reporting brought implementation challenges. Financial advice reform prompted discussion about the continuing difficulty of providing consumers with affordable, high-quality advice.

Those subjects remain part of wider regulatory, policy and government work, according to APRA and ASIC. What stands out from the regulators’ account is how little separation remains between the risks occupying boards. AI changes cyber risk. Cyber incidents become operational problems. Operational resilience depends on third parties. Third-party failures can become systemic events. And once the crisis begins, the quality of the governance around all of it stops being theoretical.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong